The Experts below are selected from a list of 4893 Experts worldwide ranked by ideXlab platform

Elovici Yuval - One of the best experts on this subject based on the ideXlab platform.

  • BRIGHTNESS: Leaking Sensitive Data from Air-Gapped Workstations via Screen Brightness
    'Institute of Electrical and Electronics Engineers (IEEE)', 2020
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Elovici Yuval
    Abstract:

    Air-gapped Computers are systems that are kept isolated from the Internet since they store or process sensitive information. In this paper, we introduce an optical covert channel in which an attacker can leak (or, exfiltlrate) sensitive information from air-gapped Computers through manipulations on the screen brightness. This covert channel is invisible and it works even while the user is working on the Computer. Malware on a Compromised Computer can obtain sensitive data (e.g., files, images, encryption keys and passwords), and modulate it within the screen brightness, invisible to users. The small changes in the brightness are invisible to humans but can be recovered from video streams taken by cameras such as a local security camera, smartphone camera or a webcam. We present related work and discuss the technical and scientific background of this covert channel. We examined the channel's boundaries under various parameters, with different types of Computer and TV screens, and at several distances. We also tested different types of camera receivers to demonstrate the covert channel. Lastly, we present relevant countermeasures to this type of attack. Lastly, we present relevant countermeasures to this type of attack.Comment: 2019 12th CMI Conference on Cybersecurity and Privacy (CMI

  • PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines
    2018
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Zadov Boris, Elovici Yuval
    Abstract:

    In this paper we provide an implementation, evaluation, and analysis of PowerHammer, a malware (bridgeware [1]) that uses power lines to exfiltrate data from air-gapped Computers. In this case, a malicious code running on a Compromised Computer can control the power consumption of the system by intentionally regulating the CPU utilization. Data is modulated, encoded, and transmitted on top of the current flow fluctuations, and then it is conducted and propagated through the power lines. This phenomena is known as a 'conducted emission'. We present two versions of the attack. Line level powerhammering: In this attack, the attacker taps the in-home power lines1 that are directly attached to the electrical outlet. Phase level power-hammering: In this attack, the attacker taps the power lines at the phase level, in the main electrical service panel. In both versions of the attack, the attacker measures the emission conducted and then decodes the exfiltrated data. We describe the adversarial attack model and present modulations and encoding schemes along with a transmission protocol. We evaluate the covert channel in different scenarios and discuss signal-to-noise (SNR), signal processing, and forms of interference. We also present a set of defensive countermeasures. Our results show that binary data can be covertly exfiltrated from air-gapped Computers through the power lines at bit rates of 1000 bit/sec for the line level power-hammering attack and 10 bit/sec for the phase level power-hammering attack.Comment: arXiv admin note: text overlap with arXiv:1802.0270

Guri Mordechai - One of the best experts on this subject based on the ideXlab platform.

  • BRIGHTNESS: Leaking Sensitive Data from Air-Gapped Workstations via Screen Brightness
    'Institute of Electrical and Electronics Engineers (IEEE)', 2020
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Elovici Yuval
    Abstract:

    Air-gapped Computers are systems that are kept isolated from the Internet since they store or process sensitive information. In this paper, we introduce an optical covert channel in which an attacker can leak (or, exfiltlrate) sensitive information from air-gapped Computers through manipulations on the screen brightness. This covert channel is invisible and it works even while the user is working on the Computer. Malware on a Compromised Computer can obtain sensitive data (e.g., files, images, encryption keys and passwords), and modulate it within the screen brightness, invisible to users. The small changes in the brightness are invisible to humans but can be recovered from video streams taken by cameras such as a local security camera, smartphone camera or a webcam. We present related work and discuss the technical and scientific background of this covert channel. We examined the channel's boundaries under various parameters, with different types of Computer and TV screens, and at several distances. We also tested different types of camera receivers to demonstrate the covert channel. Lastly, we present relevant countermeasures to this type of attack. Lastly, we present relevant countermeasures to this type of attack.Comment: 2019 12th CMI Conference on Cybersecurity and Privacy (CMI

  • PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines
    2018
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Zadov Boris, Elovici Yuval
    Abstract:

    In this paper we provide an implementation, evaluation, and analysis of PowerHammer, a malware (bridgeware [1]) that uses power lines to exfiltrate data from air-gapped Computers. In this case, a malicious code running on a Compromised Computer can control the power consumption of the system by intentionally regulating the CPU utilization. Data is modulated, encoded, and transmitted on top of the current flow fluctuations, and then it is conducted and propagated through the power lines. This phenomena is known as a 'conducted emission'. We present two versions of the attack. Line level powerhammering: In this attack, the attacker taps the in-home power lines1 that are directly attached to the electrical outlet. Phase level power-hammering: In this attack, the attacker taps the power lines at the phase level, in the main electrical service panel. In both versions of the attack, the attacker measures the emission conducted and then decodes the exfiltrated data. We describe the adversarial attack model and present modulations and encoding schemes along with a transmission protocol. We evaluate the covert channel in different scenarios and discuss signal-to-noise (SNR), signal processing, and forms of interference. We also present a set of defensive countermeasures. Our results show that binary data can be covertly exfiltrated from air-gapped Computers through the power lines at bit rates of 1000 bit/sec for the line level power-hammering attack and 10 bit/sec for the phase level power-hammering attack.Comment: arXiv admin note: text overlap with arXiv:1802.0270

Michael Cohen - One of the best experts on this subject based on the ideXlab platform.

  • anti forensic resilient memory acquisition
    Digital Investigation, 2013
    Co-Authors: Johannes Stüttgen, Michael Cohen
    Abstract:

    Memory analysis has gained popularity in recent years proving to be an effective technique for uncovering malware in Compromised Computer systems. The process of memory acquisition presents unique evidentiary challenges since many acquisition techniques require code to be run on a potential Compromised system, presenting an avenue for anti-forensic subversion. In this paper, we examine a number of simple anti-forensic techniques and test a representative sample of current commercial and free memory acquisition tools. We find that current tools are not resilient to very simple anti-forensic measures. We present a novel memory acquisition technique, based on direct page table manipulation and PCI hardware introspection, without relying on operating system facilities - making it more difficult to subvert. We then evaluate this technique's further vulnerability to subversion by considering more advanced anti-forensic attacks.

Bykhovsky Dima - One of the best experts on this subject based on the ideXlab platform.

  • BRIGHTNESS: Leaking Sensitive Data from Air-Gapped Workstations via Screen Brightness
    'Institute of Electrical and Electronics Engineers (IEEE)', 2020
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Elovici Yuval
    Abstract:

    Air-gapped Computers are systems that are kept isolated from the Internet since they store or process sensitive information. In this paper, we introduce an optical covert channel in which an attacker can leak (or, exfiltlrate) sensitive information from air-gapped Computers through manipulations on the screen brightness. This covert channel is invisible and it works even while the user is working on the Computer. Malware on a Compromised Computer can obtain sensitive data (e.g., files, images, encryption keys and passwords), and modulate it within the screen brightness, invisible to users. The small changes in the brightness are invisible to humans but can be recovered from video streams taken by cameras such as a local security camera, smartphone camera or a webcam. We present related work and discuss the technical and scientific background of this covert channel. We examined the channel's boundaries under various parameters, with different types of Computer and TV screens, and at several distances. We also tested different types of camera receivers to demonstrate the covert channel. Lastly, we present relevant countermeasures to this type of attack. Lastly, we present relevant countermeasures to this type of attack.Comment: 2019 12th CMI Conference on Cybersecurity and Privacy (CMI

  • PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines
    2018
    Co-Authors: Guri Mordechai, Bykhovsky Dima, Zadov Boris, Elovici Yuval
    Abstract:

    In this paper we provide an implementation, evaluation, and analysis of PowerHammer, a malware (bridgeware [1]) that uses power lines to exfiltrate data from air-gapped Computers. In this case, a malicious code running on a Compromised Computer can control the power consumption of the system by intentionally regulating the CPU utilization. Data is modulated, encoded, and transmitted on top of the current flow fluctuations, and then it is conducted and propagated through the power lines. This phenomena is known as a 'conducted emission'. We present two versions of the attack. Line level powerhammering: In this attack, the attacker taps the in-home power lines1 that are directly attached to the electrical outlet. Phase level power-hammering: In this attack, the attacker taps the power lines at the phase level, in the main electrical service panel. In both versions of the attack, the attacker measures the emission conducted and then decodes the exfiltrated data. We describe the adversarial attack model and present modulations and encoding schemes along with a transmission protocol. We evaluate the covert channel in different scenarios and discuss signal-to-noise (SNR), signal processing, and forms of interference. We also present a set of defensive countermeasures. Our results show that binary data can be covertly exfiltrated from air-gapped Computers through the power lines at bit rates of 1000 bit/sec for the line level power-hammering attack and 10 bit/sec for the phase level power-hammering attack.Comment: arXiv admin note: text overlap with arXiv:1802.0270

Eric Cole - One of the best experts on this subject based on the ideXlab platform.

  • volatile memory Computer forensics to detect kernel level compromise
    International Conference on Information and Communication Security, 2004
    Co-Authors: Sandra Ring, Eric Cole
    Abstract:

    This research presents a software-based Computer forensics method capable of recovering and storing digital evidence from volatile memory without corrupting the hard drive. Acquisition of volatile memory is difficult because it must be transferred onto non-volatile memory prior to disrupting power. If this data is transferred onto the hard drive of the Compromised Computer it could destroy critical evidence. This research will enhance investigations by allowing the inclusion of hidden processes, kernel modules, and kernel modifications present only in memory that may have otherwise been neglected. This methodology can be applied to any operating system and has been proven through implementation on Linux.